Home

Description

Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.

PUBLISHED Reserved 2025-04-24 | Published 2025-05-02 | Updated 2025-05-12 | Assigner certcc

Problem types

CWE-1391: Use of Weak Credentials

Product status

1.0
affected

References

www.kb.cert.org/vuls/id/360686

www.digigram.com/download/pyko-out-user-manual-en-jan-2019/

cve.org (CVE-2025-3927)

nvd.nist.gov (CVE-2025-3927)

Download JSON